Skip to content

Capability matrix

The capability matrix defines explicit permissions across Rival Enterprise. It details which platform actions each role can perform directly, which actions require administrative approval, and which actions are restricted.

= full access · = restricted · = not applicable for that role.

  • Standard Rival User — self-serve individual account operating outside an enterprise workspace boundary.
  • Enterprise Admin — IT and operations administrators with global governance and workspace management authority.
  • Enterprise Team Member — enterprise employees building and executing automations within pre-established company guardrails.

For the narrative description of each role, see Roles overview.

Feature / actionStandard UserEnterprise AdminEnterprise Team Member
Manage workspace settingsFull (personal)Full (org-wide)View only
Manage SSO and identity sync
Configure global guardrails
Manage users and invitations
Create and manage teamsView assigned
Manage billing and run balanceOrg-wide controlView assigned balance
View audit logsGlobal visibilityTeam-scoped

See Account settings, SSO setup, Guardrails and allowed models, and Audit logs.

Feature / actionStandard UserEnterprise AdminEnterprise Team Member
Build tools via RivalBotGuided / governed
Write custom code handlersRole permitted
Attach workspace secretsPersonal secretsOrg-wide secretsAdmin approved only
Run interactive tests
Publish to org marketplaceDirect (org-wide)Requires admin approval
Deprecate published toolsPersonal assetsOrg-wide assetsAssigned assets only

Secret handling is covered in Secrets.

Feature / actionStandard UserEnterprise AdminEnterprise Team Member
Set up enterprise connectorsOrg-level setup
Assign connector access
Use approved connectorsPersonal onlyAssigned / approved only
Request new system connectionsDirect additionIn-app request

See Connector governance and security.

Feature / actionStandard UserEnterprise AdminEnterprise Team Member
Execute approved agents
Run multi-step workflows
Sign off on pending approvalsDesignated lead only
Override execution guardrails

See Approval workflows.

  • Self-serve vs. enterprise — Standard Users operate with full personal freedom over their own workspace, while Enterprise Team Members operate inside curated, admin-managed catalogs.
  • Publishing controls — Enterprise Team Members can construct tools and workflows freely, but publishing them to the shared organization catalog requires explicit Enterprise Admin review.
  • Connector boundaries — system connections are established centrally by administrators, ensuring credentials remain encrypted and isolated from end users.